Hey Splunkers!
I have a doubt, when we create any customize app in Splunk, for any purpose, lets say for log monitoring.
So the default props.conf will be effective or if i update something in my Customize App's props.conf at UF level, so that will be effective for my particular sourcetype?
As i read somewhere, If the sourcetype specified in the inputs.conf of Splunk UF was not declared in the props.conf in the Splunk Indexer of Splunk HF, the attributes of the sourcetype will take all the default props.conf settings (Line_BREAKER, TIME_FORMAT etc...) of Universal Forwarder.
Thanks in advance!
Keep Splunking
↧